View Full Version : Malware Analysis and Unpacking Forum
Pages :
1
[
2]
3
4
5
6
7
8
9
- 【Help】Please analyze the code (2 replies)
- How to solve this trick ? (12 replies)
- How to unpack this? (8 replies)
- Unpacking WinLicense (17 replies)
- found: Practical Malware Analysis (1 replies)
- Orer AKA W32/Hunk.a (0 replies)
- Very suspicious packed file (13 replies)
- Fake crackme on crackmes.de? (10 replies)
- Unpack securom 5.00.03 (21 replies)
- Yoda's Crypter 1.2 (13 replies)
- VM detection via VERR/VERW (13 replies)
- Example for nice custom obfuscation (7 replies)
- To start with malwares (8 replies)
- WORM/Nuj.A.124 - Something to play with... (0 replies)
- Debugged program unable to process exception (10 replies)
- help: packer identification (10 replies)
- PC Guard (9 replies)
- Strange section within EXE (3 replies)
- Packed sdbot variant (14 replies)
- SWF Encrypt (Flash 'obfuscator') hacking (30 replies)
- Who is working for an AV company? (12 replies)
- winlogon (14 replies)
- Quick Unpack v1.0 final (1 replies)
- Change file to work right (1 replies)
- possibble rootkit kdjfq.exe (3 replies)
- Malware (packed, polymorphic) dll. Pecompact 2.xx? (9 replies)
- the drivers are peed or wincom32 probably but the exe isnt detected by norton (11 replies)
- Article: "Stealth for Survival: Threat of the Unknown" (0 replies)
- AsProtect 2.2. Help with find OEP (4 replies)
- Recently appeared virus supposed to be from the German BKA :) (23 replies)
- Unwrapping PACE Interlok v5.5.0.2618 (7 replies)
- Malware fight (22 replies)
- Suspicious file - Can't unpack (8 replies)
- Me code write good: The l33t skillz of the virus writer (71 replies)
- Capture, care and analysis of Malware made easy (4 replies)
- PE GRUM Virus and Some Search Engine Poisoning malware (7 replies)
- a nice paper on a trojan/malware (3 replies)
- Another trojan I couldn't identify the packer (7 replies)
- Another strange packer (2 replies)
- Strange Packer (5 replies)
- arma's processes (4 replies)
- Armadillo + other protections... (6 replies)
- Malware and Virtual Environments (3 replies)
- Old Stuff (2 replies)
- 2 malware video tutorials by Fifo (16 replies)
- Norwegian Bank Malware Analysis (0 replies)
- BIOHAZARD bags (0 replies)
- Malware analysis: Nailuj sys file (6 replies)
- Malware Forum RULES (3 replies)
- Ways to detect the difference between a packed and unpacked exe in memory (8 replies)
- Arma is breeding like a rabbit! (4 replies)
- Quality of WinLicense (2 replies)
- Malware Analysis: "Skype" Trojan (6 replies)
- Role of Imprec (7 replies)
- OVERLAY (1 replies)
- A new software protection method (Objantihack) (8 replies)
- Odd problem with Acudata (0 replies)
- SafeDisc 4.60 and on... (7 replies)
- HASP DOS Envelope (0 replies)
- re-write a MemoHasp-1 memory (0 replies)
- .NET dump (2 replies)
- armadillo I think, date check (5 replies)
- unknown packer / nice anti-olly trick (2 replies)
- Symbian 9.x ... how to decompress ?! (7 replies)
- Problem with Custom Armadillo Implentation (13 replies)
- [ARTeam] HASP SL - A Deeper Dig by potassium (6 replies)
- Packing / unpacking of Flash SWF files (yes, really!) (29 replies)
- Strange Packer (11 replies)
- 100% Unpacking Flash's tuts (8 replies)
- safedisc problem (27 replies)
- PECompact v1.67 Delphi DLL (9 replies)
- FSG 2 and Delphi... (0 replies)
- Another unknown (11 replies)
- Yoda's Protector 1.3 (17 replies)
- Themida - VirtualAllocMemory of four bytes (5 replies)
- WIBU WkbCrypt2 (WITH dongle) (77 replies)
- HardLock Envelope unpacking (WITH dongle) (19 replies)
- Merging Imports with Exports? (4 replies)
- Safedisc dump (8 replies)
- Updating a Wise installation package (1 replies)
- How to extract a Install Shield 10.5 project (9 replies)
- Extracting java classes from exe ? (9 replies)
- SerialShield (2 replies)
- Code to find IAT (9 replies)
- Having trouble with an ARTtut.....arma related (18 replies)
- ASProtect 2.1x SKE (3 replies)
- Looking for the following tuturials (7 replies)
- ARTeam: TheMida_defeating_ring0_by_deroko (25 replies)
- What the heck is this (25 replies)
- Unpacking question (13 replies)
- Can't get the Import table right (3 replies)
- Help ACProtect (2 replies)
- help on asprotect (4 replies)
- unpacking pcguard registred app if you have a working serial!!! (2 replies)
- Unpacking Softwrap with .locked and .sw2 (5 replies)
- Problem identifying packer/encypter (22 replies)
- Execryptor (old versions) WANTED!!! (1 replies)
- Pe Section Table - How To Get Large Gaps Between Sections? (12 replies)
- New [ARTEAM] Tutorials (2 replies)
- Armadillo V4.0-V4.4.Standard.Protection UnPacK Script (8 replies)
- MSLRH V0.32 + MSLRH V0.32a UnPacK Script (8 replies)
- Z3NMiDA - Project (4 replies)
- using imprec problem (4 replies)
- New site dealing with packers (0 replies)
- Unpacking AsPack Problem Help need (18 replies)
- Looking for a GOOD packer/crypter (9 replies)
- what is this packer? (11 replies)
- Need help with Armadillo. (0 replies)
- Unusual UPX activity (8 replies)
- Armadillo 3.x - Related to Serial Registration (12 replies)
- Unpacking Armadillo 1.8 (I think) (16 replies)
- Xitech KONxiSE v1.0 - v1.1 (0 replies)
- Unknown packer (sorry) (7 replies)
- Article on Execryptor 2.2.50 (14 replies)
- Making own compressor... (3 replies)
- Yet another Armadillo question (2 replies)
- Armadillo, compendio de - season 2 (12 replies)
- pc guard 4.15 unpacking help needed (0 replies)
- Unfamiliar packer (0 replies)
- Unpacking sound files?? (6 replies)
- What is Armadillo CC meaning? (2 replies)
- PACE interlok TPKD anti-debug tricks (5 replies)
- Why i can't break at WaitForDebugEvent (2 replies)
- [ARTeam] Writing Loaders for Dlls: theory and techniques (0 replies)
- Armadillo 3.xx on a strange Target (4 replies)
- [ARTeam] New tutorial (0 replies)
- [ARTeam] Unpacking.ActiveMark.v5.x.Advanced.Part2 (3 replies)
- ASProtect 1.23 RC4 - 1.3.08.24 PROBLEM (16 replies)
- .net app help me (2 replies)
- Gleam v1.00 (3 replies)
- Exeshield with a .net app (10 replies)
- UPX Help (9 replies)
- Problem after removing HASP envelope (9 replies)
- Armadillo Help (15 replies)
- Asprotect SKE 2 Advanced import protection rebuilder + tutorial (8 replies)
- [ARTeam] Unpacking.ActiveMark.v5.x.Basic.Part1 (4 replies)
- Asprotect SKE 2.11 unpacking tutorial (2 replies)
- Little help with execryptor (8 replies)
- files .INX (1 replies)
- AKIRA AGAINST THEMIDA (18 replies)
- Delphi App PEiD Entropy : 7.21 (Packed) (10 replies)
- WsaStartUp (3 replies)
- The return OF AKIRA to crackslatinos with a big tut XTREME PROTECTOR (1 replies)
- Need Help in IAT Fixing on an Armadillo Protected App (11 replies)
- bp on CreateThread in armadillo 3.6 not breaking (4 replies)
- MoleBox v2.3 Pro Unpacking (1 replies)
- Armadillo version unknown (8 replies)
- Protecting software code by Guards (27 replies)
- Clipper packer : noclip41 (0 replies)
- Aspr dump problem (7 replies)
- PE Hardlock (1 replies)
- armadillo DUMPING problem (7 replies)
- asprotect 2.0 inline patching with asprapi (9 replies)
- Acprotect help whit bad jumps. (2 replies)
- problem running unpacked file (6 replies)
- starforce 3 question (6 replies)
- Armadill0 4.05 or 4.10 (28 replies)
- ACI 2005 (C) [Armadillo Code Injection] (28 replies)
- sentinel (1 replies)
- Identifying a packer, PEiD/TrID fail (34 replies)
- New Vbox Name HASP SL (0 replies)
- dillo fingerprints :( :( :( :( :( (0 replies)
- how to identify if a file is packed more than once? (1 replies)
- Unpacking some packers VIII (2 replies)
- PE packer identification and Anti-Ollydbg (1 replies)
- unknown armadillo (20 replies)
- armadillo nanomites (0 replies)
- SoftWrap 6.1.1 unpacking tuts (3 replies)
- Anti Debugging ? ? (8 replies)
- Execryptor (28 replies)
- Suspending a riot process..how? (4 replies)
- ARMADILLO 3.78 HELP NEEDED (10 replies)
- ASProtect 1.3 Problem (2 replies)
- decrypt decompile precompiled resources (3 replies)
- armadillo unpacking problem (1 replies)
- Need help figuring out code from unpacker. (12 replies)
- How to unpack an ASProtected .dll? (2 replies)
- +Splaj Awave tutorial revisited. (11 replies)
- Trouble with Unpacking Crypkey 5.6 (13 replies)
- Automated Imports Reconstruction (6 replies)
- unpack hasp enveloped file (0 replies)
- the new packer (8 replies)
- Ollybug (5 replies)
- Unpacking help - possible armadillo (4 replies)
- NEOLITE 2.0 UNPACK (8 replies)
- asprotect 2.0x working tut? (17 replies)
- Honeynet RE challenge (28 replies)
- Indentifing Armadillo version & unpacking (1 replies)
- ASPR IAT (0 replies)
- ASPACK problems with DLL (relocations?) (3 replies)
- Star Force 3.3 Cracked! (4 replies)
- Hard Objetive!! (0 replies)
- ActiveMa** unpacking (11 replies)
- Installshield 7 exe fun (13 replies)
- How to repack a file (4 replies)
- Wrapper question (2 replies)
- More Armadillo Stuff (2 replies)
- SafeDisc 2/3 IAT Rebuilding (4 replies)
- A strip of code in the an UnpackFile (2 replies)
- What is the sentence mean? (4 replies)
- Vbox 4.6.2 confusion (30 replies)
- Fool PEiD (6 replies)
- Why the program crashed (7 replies)
- another aspr question (5 replies)
- Aspack 2.12? Maybe... (3 replies)
- Powerfull tool to successfully unpack (7 replies)
- Sticked in by the debugging loop (3 replies)
- I can't find the OEP (2 replies)
- Sentinel Super Pro Shelled files problem (5 replies)
- Why remove my thread? (2 replies)
- PKLITE32 1.1's signature (2 replies)
- what fuction of this code be done (3 replies)
- Vbox 4.6.2[Im stuck] please help (14 replies)
- Is the code at wrong direction? (2 replies)
- QuickUnpack DLL release (2 replies)
- how to get the point of the CONTEXT STRUCT (4 replies)
- a SEH CONTEXT' Question (1 replies)
- Is it possible! (5 replies)
- Aramadillo 3.0-3.6 (3 replies)
- Unknown packer (0 replies)
- Unpacking Vbox (7 replies)
- "General extraction error", the hidden face of armadillo? (17 replies)
- IAT Rebuilding of a safecasted dll (2 replies)
- Installshield self extracting-exe ...possible? (0 replies)
- problems with a program protected by aspack + aspr (3 replies)
- Sentinel SuperPro: IDA sigs, function #'s, & shell (2 replies)
- Windows NT System-Call Hooking (3 replies)
- Interlok v5 exploration... (3 replies)
- Sentinel SuperPro Emulator (24 replies)
- Unpacking Execrytor (7 replies)
- CrypKey 6.0 for Newbie? (8 replies)
- Coding ASPACK dumper (4 replies)
- Seems like Arma detects virtual PCs.. (7 replies)
- Aspr Exception Handler Emulation notes (2 replies)
- Nice trick to hide Olly to most controls.. (17 replies)
- Wibu dongle unpacking (13 replies)
- question about armadillo packed dll & IAT (4 replies)
- Safedisc (v1) and ollydbg (2 replies)
- Microsoft C# and Basic .NET (3 replies)
- new aspr 1.31 un-dumpable? (16 replies)
- inline patching asprotect (5 replies)
- MFVDasm, Softlockx, and Bitarts PHASE1 (could use some help :-) (0 replies)
- Delphi dumped apps (16 replies)
- PC-Guard 5.0's code XORing (2 replies)
- Import Table: Working with IAT, ImpRec (4 replies)
- Nasty Nag removal (12 replies)
- Protection plus (1 replies)
- ocx unpack header? (16 replies)
- Unpacking Neolite 2 (exe, dll) (3 replies)
- Armadillo is down... (2 replies)
Powered by vBulletin® Version 4.2.2 Copyright © 2018 vBulletin Solutions, Inc. All rights reserved.